tuta.com — 87/100 (Low privacy risk)

Last analyzed

Run a new analysis on another policy

Tutao GmbH · tuta.com

Report details

Low privacy risk

Tuta is a highly privacy-friendly encrypted email provider that stores all user data end-to-end encrypted in Germany, collects minimal metadata, uses no cookies, and shares data with third parties only for payment processing or under court order.

Tutao GmbH (Tuta) demonstrates strong privacy practices centered on end-to-end encryption and data minimization. All user content is encrypted so that even Tuta cannot access it. Only essential metadata (email addresses, timestamps) remains unencrypted. Data is stored exclusively in ISO 27001 certified German data centers. Third-party sharing is limited to payment processors. The policy is transparent and references specific GDPR legal bases. Areas of concern include the campaign analysis feature that hashes IP addresses and user agents with campaign IDs under legitimate interest rather than consent, and the policy's silence on AI/model training. Law enforcement disclosure is possible under court order, though encrypted content would be inaccessible to Tuta.

Last analyzed
SourceURL

Category Assessment

Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.

Data MinimizationGood

End-to-end encryption of all user data, no cookies, only essential metadata stored unencrypted, and IP addresses stored only in anonymized form.

TransparencyGood

Policy clearly specifies each data category collected, its purpose, legal basis under GDPR, and retention periods with specific article references.

Third-party SharingGood

Data shared only with payment processors (credit institutions, PayPal) and law enforcement under court order; explicit statement that no data is sold.

International TransfersGood

All data stored in ISO 27001 certified data centers in Germany with no mention of any transfers outside the EU/EEA.

AI/Model TrainingFair

Policy is completely silent on AI or model training; while Tuta's encryption model makes unauthorized use unlikely, explicit confirmation is absent.

User RightsGood

Comprehensive listing of GDPR rights (Articles 15-20, 21, 77) including access, rectification, erasure, restriction, portability, objection, and complaint to supervisory authority.

Key Findings

Notable clauses, issues, or positive practices discovered (critical first)

Info

Campaign analysis processes hashed identifiers under legitimate interest without explicit consent

The policy states that when users arrive via campaign links, Tuta stores a cryptographic hash of IP address and user agent together with a campaign ID linked to the Tuta account. This is processed under Art. 6(1)(f) legitimate interest rather than consent. While the hash is claimed to prevent re-identification, the combination of hash + campaign ID + account linkage means Tuta can associate campaign attribution with specific users for 30 days. This is a form of tracking that relies on legitimate interest balancing rather than user consent.

Info

Law enforcement disclosure clause could compel inventory and traffic data

The policy states: 'we can be legally bound to provide content data and traffic data (in case of a valid court order) and inventory data to law enforcement agencies.' While end-to-end encryption protects content from Tuta's own access, inventory data (email address, name, billing address) and traffic data (metadata such as sender/recipient addresses and timestamps) could be disclosed. Users should understand that metadata is not end-to-end encrypted and is accessible to Tuta and thus to authorities.

Info

Email metadata is stored unencrypted and accessible to Tuta

The policy explicitly states: 'Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted.' This means that while email content is protected by end-to-end encryption, the social graph of who communicates with whom and when is visible to Tuta and could be disclosed under court order. Mail server logs containing sender/recipient addresses and connection times are retained for up to 7 days.

Info

No cookies and no third-party analytics tools used

The policy explicitly states 'We do not use cookies' and 'we do not use analysis tools such as Google Analytics or other third-party tools.' Usage statistics are opt-in, anonymized, and self-hosted. This is a notably strong anti-tracking stance that eliminates common web surveillance vectors.

Info

Data retention after account termination has exceptions that could extend storage significantly

While the default is deletion within 30 days of contract termination, the policy lists multiple exceptions: accounting data may be retained until fee disputes are resolved, inventory data can be stored for up to two years for complaint handling, and deletion may be omitted where legal regulations or prosecution of claims require it. Tax, contract, and commercial law retention periods also apply to order-related data. These exceptions could result in some personal data persisting well beyond the 30-day baseline.

Consumer Takeaway

Tuta is one of the strongest privacy-oriented email services available, with genuine end-to-end encryption that even Tuta itself cannot bypass, though users should be aware that email metadata and campaign tracking data are not encrypted.

Compliance Posture

Tuta demonstrates strong GDPR compliance with a German-based controller, appointed DPO, clear legal bases for each processing activity, and comprehensive data subject rights documentation.

EU Transfers

No international transfers. All data is stored exclusively in ISO 27001 certified data centers in Germany, within the EU/EEA.

Detected Signals

Specific data points and practices identified in the text

Data Collected
Email addressCountry of domicileName and invoicing addressVAT identification numberBanking detailsCredit card dataPayPal usernameEmail metadata (sender/recipient addresses, dates)Mail server logs (sender/recipient addresses, connection time)Anonymized IP addressesDevice typesGeolocation of IP addressesCampaign IDCryptographic hash of IP address and user agentSearch keywords and queries (campaign analysis)Usage statistics (if consented)Contact form submissions
Processing Purposes
Service provision and contract performanceInvoicing and VAT determinationPayment processingEmail service operationAbuse preventionError diagnosisWebsite and app improvement (anonymized, legitimate interest)Usage statistics (with consent)Campaign analysis (legitimate interest)Legal compliance and law enforcement response
Third-party Sharing
Payment data shared with credit institutions for direct debitPayment data shared with PayPal (Europe) for PayPal transactionsInventory and traffic data may be disclosed to law enforcement under court orderNo data sold to third partiesNo third-party analytics tools usedAnonymized usage data may be used for research purposes
International Transfers
All data stored in ISO 27001 certified data centers in GermanyNo international transfers mentionedGerman data protection law applies as controller is based in Hannover, Germany
AI / Model Training
Policy is completely silent on AI or model trainingEnd-to-end encryption makes content inaccessible for trainingNo mention of automated decision-making or profiling

Evidence Snippets

Direct quotes from the policy supporting these findings

All user data is stored end-to-end encrypted in Tuta. Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted.

We do not use cookies.

In order to evaluate campaigns with partners and advertising campaigns...we store a cryptographic hash of connection data like the IP address and the user agent...together with the campaign ID when you visit our website via a campaign link.

The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case.

However, we can be legally bound to provide content data and traffic data (in case of a valid court order) and inventory data to law enforcement agencies. There will be no sale of data.

Missing or Unclear

  • Explicit statement on whether user data is used for AI or model training
  • Details on data portability implementation (how to export data in machine-readable format)
  • Specific retention periods for each data category beyond the general 30-day post-termination rule
  • Whether campaign analysis can be opted out of
  • Details on sub-processors beyond payment providers
  • Whether Tuta has received law enforcement requests and published transparency reports

Questions to Ask

  • How does Tuta implement the right to data portability (Art. 20 GDPR) for end-to-end encrypted data — can users export their encrypted and unencrypted data in a structured, machine-readable format?
  • Can users opt out of campaign analysis tracking, or is the legitimate interest balancing the only recourse via the right to object under Art. 21 GDPR?
  • Has Tuta published a transparency report detailing the number and types of law enforcement requests received and how they were responded to?
  • What specific anonymization technique is used for IP addresses, and has Tuta assessed whether the combination of anonymized IP, device type, and geolocation could lead to re-identification?
  • Does Tuta use any user data (including metadata or anonymized usage statistics) for training machine learning models or AI systems?
  • What happens to the campaign analysis hash and campaign ID data if a user deletes their account during the 30-day retention window?
This analysis is generated by AI and is not legal advice. Always consult a qualified legal professional for compliance decisions.

Share this analysis

Anyone with this link can view the result above.

Built by DentroChat

100% European AI chat for everyone

Chat with AI, work with files, generate images, and search the web. Data stays in Europe.

EU-hosted infrastructureText, files, images & web searchFast, Thinking & Creative modesPrivacy-first by defaultNo data leaves Europe
Try free →
View all